Question 12 of 28: Invariant Strengthening Under Inheritance
Nivaar worked solution (AI-drafted; not reviewed by a licensed engineer)
Notes on this paper
98-Comp-B11 Advanced Software Design — National Exams, May 2016. 3 hours, closed book exam with one aid sheet allowed (written on both sides), no calculator permitted. The paper is organized into five parts, and candidates were instructed to answer any five (5) questions in Part I, any three (3) in Part II, any four (4) in Part III, any two (2) in Part IV, and any five (5) in Part V — only the first questions answered, in each part, as they appear in the answer book are marked. All questions carry equal weight, so the 19 questions actually marked (5+3+4+2+5 of 28) each count for 100/19 ≈ 5.26% of the paper. All 28 questions are answered below for completeness.
Reference texts: Sommerville, Software Engineering (10th ed., Pearson) — software processes, requirements engineering, agile methods, design principles, dependability; Pressman, Software Engineering: A Practitioner's Approach (9th ed.) — supplementary process and quality coverage; Gamma, Helm, Johnson & Vlissides (GoF), Design Patterns: Elements of Reusable Object-Oriented Software — creational/structural/behavioural pattern catalogue (Singleton, Proxy, Template Method, Observer, etc.); Sebesta, Concepts of Programming Languages (12th ed.) — polymorphism, dynamic binding, inheritance and language-level object semantics; Bertrand Meyer, Object-Oriented Software Construction — design by contract, preconditions/postconditions/invariants, the open–closed principle; Barbara Liskov's 1987 substitutability paper for Question 11; Rogers, Sharp & Preece, Interaction Design, and Nielsen, Usability Engineering, for Question 21's HMI-specific non-functional requirements; Myers, The Art of Software Testing, for Question 28's boundary value analysis.
PART I — General Principles (answer any 5 of 7)
Question 12: Invariant Strengthening Under Inheritance (Part II)
Yes, this is acceptable. Under LSP (Question 11), a subclass invariant is safe precisely when it is formed by CONJOINING (adding clauses to) the inherited invariant rather than replacing or weakening it — conjunction can only narrow, never broaden, the set of states an instance may occupy, so a B instance can never violate anything A's clients rely on.
Class B's full invariant is therefore the inherited clause AND the new clause: (x ≥ 0 AND y = 0) AND (x ≥ 0 implies y ≥ 0). Because A's own clause already forces y = 0 whenever an instance exists, the added clause x ≥ 0 implies y ≥ 0 reduces, for every state A already allows, to "if x ≥ 0 then 0 ≥ 0" — which is trivially true. The new clause is therefore logically REDUNDANT: it is automatically satisfied by every state A's invariant already permits, so B's combined invariant defines EXACTLY the same set of valid states as A's invariant alone. No new states are admitted, and none of A's forbidden states become reachable, so B trivially satisfies LSP's invariant-preservation requirement.
This is confirmed by exhaustive enumeration over integer x, y in a bounded range: every (x, y) pair satisfying A's invariant also satisfies B's added clause, and B's combined invariant is set-equal to A's invariant over the tested range.
Contrast with what would NOT be acceptable. If B had instead REPLACED A's y = 0 clause with the strictly weaker x ≥ 0 implies y ≥ 0 (dropping the original clause rather than adding to it), this WOULD violate LSP: it would newly admit states such as x = 3, y = 7 that A's invariant explicitly forbade. Any client code written against A, relying on y always being exactly 0, would then break when a B instance is substituted for an A reference — the textbook LSP violation. The distinguishing factor is not the new clause's content in isolation, but whether it is ADDED to (safe) or REPLACES (unsafe) the inherited invariant.